
How to Flush the DNS Cache on Windows, macOS, and Linux?
You've updated an A record, the new server is live, and your colleague on the other side of the office sees the new site. Your own laptop, though, keeps loading the old one. More often than not, the culprit is your operating system's DNS cache holding on to the old answer until its TTL runs out. Flushing that cache forces your machine to ask again.
This guide covers the exact commands to flush the OS-level DNS cache on Windows, macOS, and the various Linux setups, how to confirm the flush actually worked, and the other caching layers that a flush does not touch. If you want to understand why caches exist in the first place, see what DNS caching is and how it works. This article is about the operating system; clearing the separate cache inside your web browser is covered in how to clear the DNS cache in Chrome, Firefox, and Edge.
What You Are Actually Flushing
Your operating system runs a small stub resolver service that caches answers from your configured DNS server:
| OS | Caching service |
|---|---|
| Windows | DNS Client service (Dnscache) |
| macOS | mDNSResponder (with dscacheutil for the Directory Services cache) |
| Linux (most desktop distros) | systemd-resolved, or sometimes nscd or dnsmasq |
| Linux (many servers) | Often no cache at all |
When an application calls the system resolver (for example via getaddrinfo()), the OS first checks this cache. A hit returns instantly without any network traffic. A miss goes out to your configured recursive resolver, typically your router, your ISP, or a public resolver like 1.1.1.1.
Flushing empties only this local layer. It does not touch:
- The cache at your recursive resolver (router, ISP, or public DNS).
- The separate browser DNS cache in Chrome, Edge, or Firefox.
- Entries in your hosts file, which are static and override DNS entirely. See the hosts file and how it overrides DNS.
Keep that in mind; it explains most "I flushed and nothing changed" moments.
How to Flush the DNS Cache on Windows
Windows 10 and Windows 11 use the same commands. Open Command Prompt or Windows Terminal. Administrator rights are recommended; on some configurations the flush fails without them.
ipconfig /flushdns
You should see:
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
That's it for the cache itself. To view what's cached before or after:
ipconfig /displaydns
This prints every cached entry with its record type, remaining TTL, and data. After a flush, the list is short or empty (entries loaded from the hosts file reappear immediately, which is expected).
Using PowerShell
PowerShell has native cmdlets that do the same thing with more useful output:
# Show the cache as objects you can filter
Get-DnsClientCache | Where-Object Entry -like "*example.com*"
# Flush the cache
Clear-DnsClientCache
Get-DnsClientCache returns structured objects, so you can filter for a specific domain and confirm whether a stale record is present. Clear-DnsClientCache is the PowerShell equivalent of ipconfig /flushdns.
If the flush doesn't seem to help on Windows
- Renew the network lease too. If the DNS server address itself changed, run
ipconfig /releasefollowed byipconfig /renewto pick up new DHCP settings. - Reset Winsock in severe cases.
netsh winsock resetresets the network stack catalog and requires a reboot. Only use this for broader connectivity issues, not stale records. - Check for a VPN or security client. Some VPN and endpoint security products run their own DNS proxy with a separate cache.
How to Flush the DNS Cache on macOS
On all recent macOS versions, including Ventura, Sonoma, Sequoia, and Tahoe, open Terminal and run:
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
Enter your password when prompted. There's no confirmation message; silence means success.
The command does two things. dscacheutil -flushcache clears the Directory Services cache, and sending SIGHUP to mDNSResponder tells the resolver daemon to drop its cached DNS records. Running both covers the full stack on modern macOS. The killall -HUP doesn't actually kill the process; it signals it to reset.
Verifying on macOS
macOS doesn't offer a simple command to list cached DNS records the way Windows does. The practical check is to query through the system resolver and compare the result with a direct DNS query:
# Uses the system resolver (cache, hosts file, mDNS)
dscacheutil -q host -a name www.example.com
# Bypasses the OS cache and asks a DNS server directly
dig @1.1.1.1 www.example.com A +short
If both return the new address, your OS is up to date. If dscacheutil still shows the old one, check /etc/hosts and any VPN or network extension that might be intercepting DNS.
How to Flush the DNS Cache on Linux
Linux is the tricky one, because there's no single cache. What you need to run depends on what your distribution uses. First, find out:
resolvectl status 2>/dev/null | head -n 20
cat /etc/resolv.conf
If resolvectl prints per-link DNS servers, you're on systemd-resolved. If it fails and /etc/resolv.conf lists a remote server like 192.0.2.53, you likely have no local cache. If /etc/resolv.conf points to 127.0.0.53, that's systemd-resolved; if it points to 127.0.0.1, something like dnsmasq or unbound is probably running locally.
systemd-resolved (Ubuntu, Fedora, Debian desktops, and many others)
sudo resolvectl flush-caches
On older systems that predate resolvectl, the equivalent is:
sudo systemd-resolve --flush-caches
To confirm the flush, check the cache statistics before and after:
resolvectl statistics
Look at the Current Cache Size line under the cache section. It should drop to zero (or near zero) right after the flush.
nscd (Name Service Cache Daemon)
Some older or enterprise systems run nscd, which caches hostname lookups:
sudo nscd -i hosts
The -i hosts flag invalidates only the hosts cache. Restarting the service also works:
sudo systemctl restart nscd
dnsmasq
dnsmasq is common on lightweight systems, routers, and some development setups. Sending it SIGHUP clears its cache and rereads its hosts files:
sudo killall -HUP dnsmasq
Alternatively, restart the service with sudo systemctl restart dnsmasq.
Unbound or BIND running locally
If you run a full caching resolver on the machine, use its control tool. For Unbound:
# Flush one name
sudo unbound-control flush www.example.com
# Flush everything at and below a zone
sudo unbound-control flush_zone example.com
For BIND's named acting as a resolver:
# Flush the entire cache
sudo rndc flush
# Flush a single name
sudo rndc flushname www.example.com
Targeted flushes are preferable on shared resolvers, because wiping the whole cache causes a burst of upstream queries. If you're running BIND as an authoritative server rather than a resolver, see how to run your own DNS server with BIND.
No local cache
Many minimal server images have no caching service at all. Each lookup goes straight to the server in /etc/resolv.conf, so there's nothing to flush locally. If you still see stale answers, the cache is upstream.
Mobile Devices
Phones don't expose a flush command, but you can achieve the same effect:
- iPhone and iPad: toggle Airplane Mode on for a few seconds, then off. This resets network connections and the resolver cache. A restart also works.
- Android: toggle Airplane Mode, or restart the device. If you use Private DNS (DNS over TLS), switching it off and on again in network settings also forces fresh lookups.
Quick Reference
| Platform | Command |
|---|---|
| Windows (CMD) | ipconfig /flushdns |
| Windows (PowerShell) | Clear-DnsClientCache |
| macOS | sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder |
| Linux (systemd-resolved) | sudo resolvectl flush-caches |
| Linux (nscd) | sudo nscd -i hosts |
| Linux (dnsmasq) | sudo killall -HUP dnsmasq |
| Unbound | sudo unbound-control flush_zone example.com |
| BIND | sudo rndc flush |
When Flushing Doesn't Fix It
If you've flushed the OS cache and still see the old record, work outward through the layers:
- Check the browser. Chrome, Edge, and Firefox keep their own short-lived DNS cache and also reuse open connections. Restart the browser or clear its host cache.
- Check the hosts file. A forgotten entry from a past test will win over any DNS answer.
- Query your resolver directly. Compare your configured resolver with the authoritative answer:
# What your configured resolver returns
dig www.example.com A +noall +answer
# What the authoritative nameserver returns
dig @$(dig example.com NS +short | head -n 1) www.example.com A +norecurse +noall +answer
The first command shows the record and its remaining TTL from your resolver's cache; the second asks one of the domain's own nameservers. If they differ, your resolver is still caching the old answer, and you either wait for the TTL to expire or switch resolvers.
- Purge a public resolver's cache. Google Public DNS and Cloudflare 1.1.1.1 both offer web forms to request a cache purge for a specific name. Your ISP's resolver usually has no such option.
- Wait out the TTL. If the old record had a long TTL, some resolvers will hold it until it expires. Read what a TTL is in DNS to plan this ahead next time, and how to check if DNS changes have propagated to see who still has the old value.
For a domain that stopped resolving entirely rather than showing an old value, the problem is probably not caching; see why a domain may not resolve after a DNS change.
Is Flushing Safe?
Yes. Flushing only removes cached copies of public data. The next few lookups take slightly longer because they go out to the network, and then the cache refills naturally. There's no reason to flush routinely; it's a troubleshooting step for when you know a record has changed or a cached failure is sticking around. Negative answers are cached too, so flushing also helps when a name didn't exist a few minutes ago but does now.
Flushing the DNS Cache FAQ
On macOS and Linux, yes, the commands require sudo. On Windows, ipconfig /flushdns often works from a normal prompt, but running it as administrator avoids permission errors on locked-down machines.
No. Browsers keep their own DNS cache and a separate HTTP cache for files. Flushing the OS cache affects neither; restart the browser or clear its host cache separately.
Only when you need to, such as after a DNS change or when a site resolves to the wrong address. Routine flushing offers no benefit and briefly makes lookups slower.
Entries from the Windows hosts file are loaded into the cache and reappear immediately after a flush. That's normal; they're static and not fetched from DNS.
Not in general. It can fix a broken or stale lookup, but a warm cache is actually faster than an empty one because answers don't need to be fetched again.
Many minimal server distributions don't run a local caching resolver by default. Lookups go directly to the server listed in /etc/resolv.conf, so there's nothing local to flush.
No. The OS cache is local to your machine. To clear cached answers for everyone, you'd need to flush the router's or the network resolver's cache instead.
Sometimes. If the error comes from a stale or cached negative answer, a flush helps. If the record is genuinely missing or the nameservers are broken, you'll need to fix the DNS configuration itself.
Conclusion
Flushing the operating system's DNS cache is a one-line fix: ipconfig /flushdns on Windows, sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder on macOS, and sudo resolvectl flush-caches on most modern Linux desktops, with the equivalents for nscd, dnsmasq, Unbound, and BIND when those are in play. The harder part is knowing whether the OS cache is actually the layer holding the stale answer.
Treat the flush as one step in a methodical check. Clear the OS cache, then compare what your resolver returns with what the authoritative nameserver says. If those still disagree, the stale data is upstream, and the right move is to purge the public resolver's cache or wait out the TTL, not to keep flushing your laptop.
For official documentation on the tools used above, see these references:
- Microsoft Learn: ipconfig command reference — documents
/flushdns,/displaydns, and the other ipconfig switches. - Microsoft Learn: Clear-DnsClientCache — the PowerShell cmdlet for clearing the Windows DNS client cache.
- freedesktop.org: resolvectl manual — reference for
flush-caches,statistics, and other systemd-resolved commands. - Google Public DNS: Flush Cache — request a cache purge for a specific name on Google's resolver.
- Cloudflare: Purge Cache for 1.1.1.1 — Cloudflare's tool for purging a name from the 1.1.1.1 resolver cache.


